NuytsTech Security

CVE-2026-24980

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in NooTheme Visionary Core noo-visionary-core allows Reflected XSS.This issue affects Visionary Core: from n/a through

CVE-2026-24979

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in NooTheme Jobica Core jobica-core allows Reflected XSS.This issue affects Jobica Core: from n/a through

CVE-2026-24978

Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection.This issue affects Jobica Core: from n/a through

CVE-2026-24977

Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in NooTheme Organici Library noo-organici-library allows Blind SQL Injection.This issue affects Organici Library: from n/a through

CVE-2026-24976

Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection.This issue affects Organici Library: from n/a through

CVE-2026-24975

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in NooTheme Organici Library noo-organici-library allows Reflected XSS.This issue affects Organici Library: from n/a through

CVE-2026-24974

Deserialization of Untrusted Data vulnerability in NooTheme CitiLights noo-citilights allows Object Injection.This issue affects CitiLights: from n/a through

CVE-2026-24973

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in NooTheme CitiLights noo-citilights allows Reflected XSS.This issue affects CitiLights: from n/a through

CVE-2026-24972

Missing Authorization vulnerability in Elated-Themes Elated Listing eltd-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elated Listing: from n/a through

CVE-2026-24971

Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through

CVE-2026-24970

Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in designingmedia Energox energox allows Path Traversal.This issue affects Energox: from n/a through

CVE-2026-24969

Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in designingmedia Instant VA instantva allows Path Traversal.This issue affects Instant VA: from n/a through

CVE-2026-24968

Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through

CVE-2026-24964

Server-Side Request Forgery (SSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Server Side Request Forgery.This issue affects Contest Gallery: from n/a through